Secure Remote Services
Vendor:
First CVE: Mar 12, 2015 · Active for 11 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Remote Services over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2015
11 years ago
Most Recent CVE
Oct 18, 2018
2,837 days ago
CVE Severity & Scoring
Secure Remote Services8 CVEs
38%
63%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (25.0%)
Network2 (25.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None4 (50.0%)
Unknown4 (50.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None1 (12.5%)
Unknown4 (50.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0544HIGH EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hij | Jul 5, 2015 | 9.3 | 28 | NO | NO |
CVE-2018-11080HIGH Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-r | Oct 18, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-11079HIGH Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration | Oct 18, 2018 | 7.8 | 24 | NO | NO |
CVE-2015-0525HIGH The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vect | Mar 12, 2015 | 7.5 | 20 | NO | NO |
CVE-2015-0524HIGH SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary S | Mar 12, 2015 | 7.5 | 20 | NO | NO |
CVE-2017-4986MEDIUM EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system. | Jun 14, 2017 | 5.3 | 16 | NO | NO |
CVE-2015-0543MEDIUM EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof | Jul 5, 2015 | 5.8 | 16 | NO | NO |
CVE-2015-6852MEDIUM Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted paramet | Dec 28, 2015 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Secure Remote Services
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.18 | 1 | 5.3 | 1.8% | 0 | 0 |
| 3.04 | 2 | 7.5 | 1.6% | 0 | 0 |
| 3.03 | 5 | 6.9 | 2.2% | 0 | 0 |
| 3.02 | 5 | 6.9 | 2.2% | 0 | 0 |
| 3.0 | 1 | 4.3 | 2.0% | 0 | 0 |